Role Overview
We are looking for a senior security leader to define and scale end-to-end Product Security across modern cloud-native and AI-driven systems.
You will own security across the full lifecycle—from secure design and threat modeling, to DevSecOps pipeline security, to AI/LLM security governance, to vulnerability management and PSIRT operations.
This is a hands-on leadership role requiring deep technical expertise and the ability to influence engineering teams at scale while enabling fast, secure product delivery.
What You Will Own (Outcomes)
1. Secure-by-Design Engineering
- Define and enforce Secure SDLC standards across product engineering teams
- Lead architecture-level security reviews for high-risk systems and features
- Drive threat modeling (STRIDE / MITRE ATT&CK)
- Establish reusable secure design patterns (identity, secrets, crypto, data protection)
2. DevSecOps at Scale
- Embed security controls into CI/CD pipelines (shift-left + shift-right)
- Operationalize SAST / SCA / Secrets scanning / IaC security
- Implement DAST and runtime security validation
- Drive SBOM generation, artifact signing, and provenance controls
- Define release security gates and remediation SLAs
Embed security controls in CI/CD pipelines (pre-commit- deploy): SAST, SCA, secret scanning, IaC/K8s policy-as-code, SBOM generation, artifact signing and provenance.
- Operationalize DAST via Veracode integration patterns and developer runbooks; track fix SLAs, break-glass criteria, and remediation metrics.
- Partner with Cloud & Platform teams to ensure telemetry, detection, and incident hooks align with SOC/SIEM runbooks.
3. AI / LLM & Data Security
- Define and implement AI/ML and LLM security controls
- Secure AI lifecycle: training, inference, deployment
- Mitigate prompt injection, data leakage, and model abuse risks
- Enforce data protection via DLP frameworks (e.g., Microsoft Purview)
- Establish AI governance, lineage, and monitoring .
- Engineer AI security guardrails: prompt/input validation, output filtering, model abuse monitoring, adversarial testing (prompt injection, data exfiltration, hallucination risk), dataset/model lineage, and access controls.
- Integrate AI security tests into CI/CD pipelines and enforce Microsoft Purview DLP policies to prevent data leakage in AI-assisted development.
4. Product Security Incident Response (PSIRT)
- Lead vulnerability intake, triage, and coordinated disclosure
- Drive patching, remediation tracking, and customer communication
- Align PSIRT with supply chain and GRC frameworks
- Track KPIs (MTTR, vuln aging, exploitability, SBOM coverage)
5. Security Leadership & Metrics
- Define product security metrics and reporting
- Influence engineering leadership and drive adoption of standards
- Act as a trusted advisor across Product, Engineering, and Security teams
Basic Qualifications
- 8+ years in Application Security / Product Security / Security Engineering
- 3+ years leading DevSecOps or AppSec programs
- Strong experience with CI/CD security (Azure DevOps / similar)
- Hands-on expertise in SAST, DAST, SCA, threat modeling
- Experience securing cloud-native systems (AWS / Azure / GCP)
Preferred Qualifications
- Experience in Product Security/AppSec roles at top-tier product companies
- Experience building or scaling PSIRT programs
- Familiarity with SBOM (SPDX / CycloneDX), SLSA, Sigstore, Cosign
- Exposure to AI/ML or LLM security in production environments
AI/ML Security Certifications & Coursework (Preferred)
- ISO/IEC 42001 Lead Implementer (AI governance and risk management for enterprise systems)
- Certified AI Risk Manager (CAIRM) (AI risk identification and mitigation)
- Training aligned to NIST AI Risk Management Framework (governance, risk, and compliance for AI systems)
Cloud AI & Security Certifications (Strong Practical Signal):
- Microsoft Certified: Azure AI Engineer Associate
- Microsoft Certified: Azure Security Engineer Associate
- AWS Certified Machine Learning – Specialty
- AWS Certified Security – Specialty
Nice to have these certifications but not mandatory or core for Product Security Manager more valuable for cloud security or AI/ML engineering roles.
‘Grant Thornton INDUS’ comprises GT U.S. Shared Services Center India Pvt Ltd and Grant Thornton U.S. Knowledge and Capability Center India Pvt Ltd. Grant Thornton INDUS is the shared services center supporting the operations of Grant Thornton LLP, the U.S. member firm of Grant Thornton International Ltd. Established in 2012, Grant Thornton INDUS employs professionals across a wide range of disciplines including Tax, Audit, Advisory, and other operational functions. What sets us apart isn’t just what we do – it’s how we do it. We support and enable the firm’s purpose of making business more personal and building trust into every result. We’re collaborators – obsessed with quality and ready for anything – who understand the value of strong relationships. Our professionals are well integrated to seamlessly support the U.S. engagement teams, help increase Grant Thornton’s access to a wide talent pool, and improve operational efficiencies. Empowered people, bold leadership, and distinctive client service are imbibed in the culture at Grant Thornton INDUS. We are a transparent, competitive, and excellence-driven firm that offers an opportunity to be part of something significant. In addition, professionals at Grant Thornton INDUS serve communities in India through inspirational and generous services to give back to the communities they work in. Grant Thornton INDUS has its offices in two locations in India – Bengaluru and Kolkata